An efficient algorithm for decomposing multivariate polynomials and its applications to cryptography

  • Authors:
  • Jean-Charles Faugère;Ludovic Perret

  • Affiliations:
  • SALSA Project, INRIA, Centre Paris-Rocquencourt, UPMC, Univ Paris 06, LIP6, CNRS, UMR 7606, LIP6, 104, avenue du Président Kennedy, 75016 Paris, France;SALSA Project, INRIA, Centre Paris-Rocquencourt, UPMC, Univ Paris 06, LIP6, CNRS, UMR 7606, LIP6, 104, avenue du Président Kennedy, 75016 Paris, France

  • Venue:
  • Journal of Symbolic Computation
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper, we present an efficient and general algorithm for decomposing multivariate polynomials of the same arbitrary degree. This problem, also known as the Functional Decomposition Problem (FDP), is classical in computer algebra. It is the first general method addressing the decomposition of multivariate polynomials (any degree, any number of polynomials). As a byproduct, our approach can be also used to recover an ideal I from its kth power I^k. The complexity of the algorithm depends on the ratio between the number of variables (n) and the number of polynomials (u). For example, polynomials of degree four can be decomposed in O(n^1^2), when this ratio is smaller than 12. This work was initially motivated by a cryptographic application, namely the cryptanalysis of 2R^- schemes. From a cryptographic point of view, the new algorithm is so efficient that the principle of two-round schemes, including 2R^- schemes, becomes useless. Besides, we believe that our algorithm is of independent interest.